Solana-based liquidity protocol Crema Finance had more than $8.78 million worth of cryptocurrencies stolen from its platform in an attack over the weekend, developers said in a tweet.

Crema said it had suspended its smart contract after the exploit. The protocol allows liquidity providers to set specific price ranges, add single-sided liquidity and conduct range order trading. This makes for a sophisticated and decentralized trading platform.

“We've been closely working with several experienced security institutes and relevant organizations to track the hacker's fund movements,” the developers said in a tweet.

Value locked on Crema plunged to $3 million on Monday from over $12 million on Saturday following the exploit, data shows. Crema has seen trading volumes of $1.34 billion since its inception in January.

The attacker started by creating a fake tick account. A tick account is "a dedicated account that stores price tick data in CLMM,” the developers said, referring to Crema's market-making protocol. After that, the attacker exploited a command by writing the data on the fake account and circumventing security measures.

The attacker then used a flash loan to manipulate the prices of assets on liquidity pools. This, along with the false data entries, allowed the attacker to claim “a huge fee amount out from the pool.”

Flash loans allow traders to borrow unsecured loans from lenders by relying on smart contracts instead of third parties.

The stolen funds were swapped to 69422.9 solana (SOL) and 6,497,738 USD Coin (USDC). The Solana-based USDC was then bridged to the Ethereum network via Wormhole and swapped to 6,064 ether (ETH). These funds amount to over $8.5 million at current prices.

The attacker’s Ethereum address, 0x8021b2962dB803b73Aa874030B0B42c202E8458F as flagged by blockchain scanning tool Etherscan, had not moved the stolen funds or converted to other coins at writing time, the data show.


All writers’ opinions are their own and do not constitute financial advice in any way whatsoever. Nothing published by CoinDesk constitutes an investment recommendation, nor should any data or Content published by CoinDesk be relied upon for any investment activities. CoinDesk strongly recommends that you perform your own independent research and/or speak with a qualified investment professional before making any financial decisions.

Join Telegram

Recommended content


Recommended Content

Editors’ Picks

Ethereum dips slightly amid Renzo depeg, BlackRock spot ETH ETF amendment

Ethereum dips slightly amid Renzo depeg, BlackRock spot ETH ETF amendment

Ethereum (ETH) suffered a brief decline on Wednesday afternoon despite increased accumulation from whales. This follows Ethereum restaking protocol Renzo restaked ETH (ezETH) crashing from its 1:1 peg with ETH and increased activities surrounding spot Ethereum ETFs.

More Ethereum News

Injective price weakness persists despite over 5.9 million INJ tokens burned

Injective price weakness persists despite over 5.9 million INJ tokens burned

Injective (INJ) price is trading with a bearish bias, stuck in the lower section of the market range. The bearish outlook abounds despite the network's deflationary efforts to pump the price. Coupled with broader market gloom, INJ token’s doomed days may not be over yet.

More Injective News

US intensifies battle against crypto privacy protocols following crackdown on Samourai Wallet

US intensifies battle against crypto privacy protocols following crackdown on Samourai Wallet

CEO Keonne Rodriguez and CTO William Lonergan of Samourai Wallet were arrested by the US Department of Justice (DoJ) on Wednesday and charged with $100 million in money laundering on a count and illegal money transmitting on another count. This move could see privacy-focused cryptocurrencies take a dip.

More Cryptocurrencies News

Near Protocol Price Prediction: NEAR fulfills targets but a 10% correction may be on the horizon

Near Protocol Price Prediction: NEAR fulfills targets but a 10% correction may be on the horizon

Near Protocol price has completed a 55% mean reversal from the bottom of the market range at $4.27. Amid growing bearish activity, NEAR could drop 10% to the $6.00 psychological level before a potential recovery. A break and close above $7.95 would invalidate the downleg thesis.

More Near Protocol News

Bitcoin: BTC post-halving rally could be partially priced in Premium

Bitcoin: BTC post-halving rally could be partially priced in

Bitcoin (BTC) price briefly slipped below the $60,000 level for the last three days, attracting buyers in this area as the fourth BTC halving is due in a few hours. Is the halving priced in for Bitcoin? Or will the pioneer crypto note more gains in the coming days? 

Read full analysis

BTC

ETH

XRP